Find White Papers
Home
About Us
List Your Papers
    
> Third Brigade > The New Threat: Attackers That Target Healthcare Organizations (And what you can do about it)

The New Threat: Attackers That Target Healthcare Organizations (And what you can do about it)

White Paper Published By: Third Brigade

Healthcare organizations are being targeted by financially motivated attackers that steal and sell valuable data, including identities and computing resources. This white paper defines the new threat, and outlines three important steps that providers can take to protect their critical systems.



Tags : 
hipaa, hipaa compliance, network security, network security appliance, security management, intrusion prevention, intrusion detection, hacker detection

Third Brigade
Published:  Aug 21, 2009
Type:  White Paper
Length:  10 pages


White paper The New Threat: Attackers That Target Healthcare
Organizations (And what you can do about it) Abstract Healthcare organizations (HCOs) are facing a new threat. They're being targeted by financially motivated attackers that steal and sell valuable data -- including identities -- and computing resources. Armed with sophisticated tools, attackers exploit countless software vulnerabilities that exist in the multitude of systems a provider relies upon, including web-based applications such EHR/EMR systems. The consequences of an attack can include reductions in quality of care, service disruptions, reduced revenues, higher operating costs, and regulatory fines. Current security approaches, including network or perimeter defenses, do not adequately protect against the new threat, and can be bypassed. It is imperative that healthcare organizations conduct a vulnerability assessment of their critical applications, and evaluate intrusion prevention as a key compensating control to mitigate the growing risk.
, Table of Contents
1. Introduction ...................................................................................................................................1 2. The New Threat............................................................................................................................1 3. Applications - The Heart of Your Healthcare Facility...................................................................3 4. Why Are Applications Vulnerable? ...............................................................................................4 5. The Consequences of an Attack ..................................................................................................4 6. Current Security Approaches Are Not Adequate..........................................................................6 7. Steps You Can Take To Reduce Your Risk .................................................................................7 8. Intrusion Prevention-Your Best, Last Line of Defense...............................................................8
1. Introduction It's a typically busy morning at the hospital, with all operating rooms booked to capacity. Down in the ER, doctors are treating a steady stream of emergencies. Over in radiology, several patients are being prepped for MRIs. But at 8:35am, the day's steady rhythm is shattered. Something's wrong. The operating room doors won't open. Shortly after, the nurses in the ICU can't log onto the computers. At 9:05, pagers stop working. And by 11am, the MRI machine has crashed, leaving a waiting room of frustrated, anxious patients. Meanwhile, a thousand miles away, a middle-aged man sits alone at his PC, and smiles to himself, as the wreckage unfolds. A few keystrokes later and he's into the database of the hospital's EHR/EMR system, calmly extracting valuable data from thousands of patients that he'll quickly sell for a tidy profit. Another Hollywood thriller, set in the distant future? Unfortunately not. Although this perfect storm of events is unlikely to occur in a single morning, this is the reality that healthcare providers operate in today. Healthcare organizations are being targeted by attackers.
2. The New Threat Until recently, attention-seeking hackers were the main IT security threat to businesses, including healthcare organizations. They would write code, unleash it into cyberspace, and hope for their 15 minutes of fame. These types of mass attacks often had no particular target in mind; they would simply seek out vulnerabilities in a system-typically in operating systems and networks-and exploit them. But that was when hackers and their motives were less dangerous. Recently though, security intelligence experts have detected "the tell-tale signs of organized crime gangs and government espionage in attacks, and a hacker community much more motivated by financial gain than
© 2006, Third Brigade, Inc 1 www.thirdbrigade.com personal or political fulfillment." (Forrester, "Increasing Organized Crime Involvement Means More Targeted Attacks", August 2, 2005) Hackers have now become attackers who target particular organizations or groups or users. Motivated by money, revenge, and perhaps in the future by terror, they take control of computing devices to steal identities and confidential data that can then be sold, to use for illegal purposes like sending spa... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search